Threat Database Trojans Trojan.Agent.Gen.BQL

Trojan.Agent.Gen.BQL

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 20,581
Threat Level: 80 % (High)
Infected Computers: 2
First Seen: April 5, 2026
Last Seen: July 28, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.Agent.Gen.BQL
Signature status: No Signature

Known Samples

MD5: 5a1d50b501c603bea3eb2b80e67a9236
SHA1: 6f3f14388eefea87f7ecce6b7b28ae2135607900
SHA256: 9D28C2875F45969ADDAC44D4EEC89E53DC8260CFD26392139F46D2F8B4F0A973
File Size: 782.85 KB, 782848 bytes
MD5: 45a5157b11ca1c2c1f0f695f32035d56
SHA1: 23429e11d28e8b624f26efa3d80ec34f5397c20d
SHA256: D0F0F75439CC939D22BE7B0BA9028F32EFAA8593A949B9135CAAB2A510815855
File Size: 782.85 KB, 782848 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name NVIDIA Corporation
File Description NVIDIA App
File Version 128.4.13.14
Internal Name NVIDIA App
Legal Copyright (C) 2017-2025 NVIDIA Corporation. All rights reserved.
Original Filename NVIDIA App.exe
Product Name NVIDIA App
Product Version 11.0.5.420

File Traits

  • x64

Block Information

Total Blocks: 153
Potentially Malicious Blocks: 24
Whitelisted Blocks: 129
Unknown Blocks: 0

Visual Map

0 0 0 0 0 0 0 0 0 x x x x x 0 0 x x x 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x 0 x x 0 x x 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 1 0 1 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
c:\programdata\windowsoptions\service2.log Read Attributes,Synchronize,Append data

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtWriteFile
  • UNKNOWN